
cobol-shield
Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

👮 👊 RegEx Denial of Service (ReDos) Scanner



CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

The Secure Coding Framework

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Link sources to sinks in C# applications.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Tool for reverse engineering of Angular applications